What the McKesson Breach Teaches Malaysian SMEs

What the McKesson Breach Teaches Malaysian SMEs — featured image

by

Your Business May Be Smaller, but the Risk Is Real

You do not need to run a hospital or pharmaceutical company to hold sensitive information. A Malaysian SME may keep customer identification details, employee records, invoices, medical certificates, delivery addresses, supplier documents and login credentials across email, cloud storage and business software.

That makes your business a potential target. Attackers often look for the easiest path into a company, not only the biggest company. One convincing message, one reused password or one careless approval can give them access to systems containing information that customers expect you to protect.

The reported McKesson incident is a useful warning because the alleged entry point was not necessarily an advanced technical exploit. The hackers claimed they used phishing and social engineering to trick employees into granting access to cloud accounts. TechCrunch reported that data allegedly included names, addresses, Social Security numbers and protected health information, although the final number of affected individuals was not confirmed. Source: TechCrunch

TL;DR

Cloud software is not automatically safe if user access is poorly managed. Your first priorities should be stronger login protection, staff awareness, limited access and a tested response plan.

Small businesses can reduce exposure by knowing where sensitive data is stored and checking who can access it.

What This Means

McKesson confirmed that hackers accessed several cloud-hosted accounts and that the incident affected parts of its operations. The company said it expected intermittent service degradation and later stated that it believed there was no ongoing unauthorised activity. Source: TechCrunch

In plain language, a cloud account is an online doorway into your business information. It may hold files, customer records, reports or connections to other systems. If an attacker obtains a valid user login, the activity can initially look like normal work. That is why security is not only about installing antivirus software. It is also about verifying requests, protecting identities and restricting what each person can do.

The alleged incident also highlights the difference between data theft and service disruption. A business may continue operating while information is being copied in the background. Alternatively, an attack may interrupt email, sales orders, stock management or customer support. Your response must address both possibilities.

Cloud security begins with controlling who can enter, what they can see and what they can do.

How This Applies to Malaysian SMEs

If you operate a clinic, tuition centre, recruitment agency, accounting practice or wellness business, you may handle highly sensitive records. Even if your company is not legally classified like a hospital, information such as identity documents, health-related notes, salary details and bank account information still deserves careful protection. A compromised shared folder could expose many customers at once.

Retailers and service businesses face a similar issue. You may collect names, phone numbers, delivery addresses, purchase histories and payment-related information through an online form, social media account or customer relationship system. A staff member who receives a fake message asking them to “verify” an account could accidentally hand over access to the customer database.

Manufacturers, wholesalers and logistics companies should look beyond customer data. Supplier price lists, quotations, purchase orders, stock levels, route information and employee documents can be valuable to criminals or competitors. If your operations depend on cloud accounting, inventory software and email, one stolen account may affect several parts of the business.

Malaysian SMEs also commonly rely on a small number of employees who perform multiple roles. An administrator might handle HR files, supplier communication and customer enquiries from the same account. This is convenient, but it creates a wide access path. When an employee leaves, changes role or uses a personal device, access may remain open unless someone actively reviews it.

Local businesses should also prepare for the communication side of an incident. Customers may ask whether their information was exposed, while staff may need clear instructions about suspicious messages. The Personal Data Protection Act 2010 and related obligations may apply depending on your business and the data you process, so you should obtain suitable professional advice rather than assume that a general response is enough.

A Simple Risk Snapshot

Business area Common information Practical control
Email Invoices, attachments, customer messages Multi-factor authentication and phishing checks
Cloud storage Identity documents, HR files, contracts Restricted folders and quarterly access reviews
Accounting software Supplier, payroll and transaction records Separate user accounts and approval controls
Customer systems Contact details and purchase history Role-based permissions and activity monitoring
Employee devices Downloads, saved passwords and business files Screen lock, updates and remote account removal

These are practical control categories, not measurements of the McKesson incident. The incident details and affected data remain subject to investigation. Source: TechCrunch

Practical Takeaways for Your Business

  • Turn on multi-factor authentication. Start with email, cloud storage, accounting, payroll and administrator accounts. A password alone should not be the only barrier.
  • Use individual accounts. Avoid shared logins such as “admin” or “sales”. Individual accounts make it easier to remove access and investigate unusual activity.
  • Teach staff to pause. Ask employees to verify urgent requests involving passwords, file sharing, payment instructions or account access through a separate channel.
  • Limit permissions. Give each person access to the files and functions needed for their role, not the entire company system.
  • Review access regularly. Check former employees, temporary staff, external vendors and old accounts at least once every quarter.
  • Protect recovery methods. Secure backup email addresses, recovery phone numbers and administrator accounts because attackers may use them to regain entry.
  • Know what data you hold. Create a simple list of systems containing customer, employee and supplier information. You cannot protect records you cannot locate.
  • Prepare an incident checklist. Include who can disable accounts, who contacts your technology provider, who informs management and who communicates with affected parties.
  • Keep offline contact details. If email is unavailable, you still need a way to reach key staff, vendors and professional advisers.
  • Practise the response. A short tabletop exercise can reveal confusion before a real incident does.

A 30-Day Starting Plan

  1. Days 1–7: List your important systems, data types and administrator accounts. Mark anything containing identity, health, payroll or financial information.
  2. Days 8–14: Enable multi-factor authentication, remove inactive users and replace shared passwords with named accounts.
  3. Days 15–21: Review staff permissions, update devices and confirm that backups can actually be restored.
  4. Days 22–30: Write your incident plan and run a short exercise based on a fake phishing message or locked cloud account.

The Bigger Picture

The long-term lesson is that cybersecurity is becoming an operational responsibility, not just an IT responsibility. A business can use excellent cloud platforms and still be exposed if employees are tricked, permissions are excessive or old accounts remain active.

For Malaysian SMEs, the practical direction is clear: build repeatable habits. New staff should receive security guidance during onboarding. Departing staff should lose access promptly. Managers should review sensitive folders and administrator accounts. Suppliers that connect to your systems should also be assessed.

You do not need a large security department to make progress. Start with the accounts and data that would cause the greatest harm if exposed. Protect those first, document the process and improve it over time. The McKesson case shows how a major organisation can face serious consequences when cloud access and human trust are abused. Your business can learn from that warning before an attacker tests your own controls.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →